An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does this by making a MD5 hash of the absolute URL of the request. If found, it servers the request. The absolute URL can include the decoded UserInfo (username and password) for certain protocols. This decoded info is prepended to the domain. This allows an attacker to provide a username that has special characters to delimit the domain, and treat the rest of the URL as a path or query string. An attacker could first make a request to their domain using an encoded username, then when a request for the target domain comes in that decodes to the exact URL, it will serve the attacker's HTML instead of the real HTML. On Squid servers that also act as reverse proxies, this allows an attacker to gain access to features that only reverse proxies can use, such as ESI.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libecap-develUpgrade libecap | May 4, 2022 | Apr 15, 2020 |
| Amazon Linux Ami 2 | — | Upgrade squidUpgrade squid-debuginfo | Sep 28, 2023 | Apr 15, 2020 |
| Centos_linux | — | Upgrade squid-debugsourceUpgrade squid-debuginfoUpgrade libecap-develUpgrade libecapUpgrade squidUpgrade libecap-debuginfoUpgrade libecap-debugsource | Nov 5, 2020 | Apr 15, 2020 |
| Debian | — | Upgrade squid | May 11, 2020 | Apr 15, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade squidUpgrade squid-migration-script | Nov 3, 2020 | Apr 15, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade squidUpgrade squid-migration-script | May 25, 2022 | Apr 15, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade squid | Aug 31, 2020 | Apr 15, 2020 |
| Oracle_linux | — | Upgrade libecapUpgrade libecap-develUpgrade squid | Oct 1, 2022 | Apr 24, 2020 |
| Redhat_linux | — | Upgrade libecap-debuginfoUpgrade libecap-debugsourceUpgrade squidUpgrade squid-debuginfoUpgrade libecap-develUpgrade libecapUpgrade squid-debugsourceNo solution exists | Nov 5, 2020 | Apr 15, 2020 |
| Rocky_linux | — | Upgrade libecap-debuginfoUpgrade libecap-debugsourceUpgrade libecap-develUpgrade libecap | Mar 12, 2024 | Apr 15, 2020 |
| Suse | — | Upgrade squidUpgrade squid3 | May 9, 2020 | Apr 15, 2020 |
| Ubuntu | — | Upgrade squid | Aug 5, 2020 | Apr 15, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub